I agree that it was a good question which shouldn't have been downvoted. But I don't think malicious developers are the real concern in this situation. Rather, it is just a matter of defensive programming. By not using hasOwnProperty (or better yet, ES6 maps), you are creating code that could break just by including a new dependency in the project.